---
schema: 1
kind: vulnerability
title: "CVE-2026-12789 — ILIAS 11.0: unpatched, PoC-public SQL injection in the learning-progress subsystem (DACH education exposure)"
headline: "CVE-2026-12789 — ILIAS 11.0: unpatched, PoC-public SQL injection in the learning-progress subsystem (DACH education exposure)"
summary: "BSI WID-SEC-2026-2016 (2026-06-22) flags CVE-2026-12789, an SQL injection in ILIAS 11.0's learning-progress tracking — specifically ilTrQuery::executeQueries in components/ILIAS/Tracking/classes/class.ilTrQuery.php (BSI WID, 2026-06-22; GitHub Advisory GHSA-69G6-PGGC-389P, 2026-06-21)."
discovered_at: "2026-06-23T04:52:47Z"
event_date: 2026-06-22
run_id: 2026-06-23-165387f6
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - sqli
  - poc-public
  - no-patch
regions:
  - dach
  - europe
sectors:
  - education
  - public-sector
entities: []
cves:
  - id: CVE-2026-12789
    cvss: "2.0"
    epss: null
    type: sqli
    vector: zero-click
    auth: post-auth
    status:
      - poc-public
      - no-patch
sources:
  - url: "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2016"
    publisher: BSI WID-SEC-2026-2016
    role: primary
  - url: "https://github.com/advisories/GHSA-69G6-PGGC-389P"
    publisher: GitHub Advisory GHSA-69G6-PGGC-389P
    role: corroborating
  - url: "https://euvd.enisa.europa.eu/enisa/EUVD-2026-38153"
    publisher: ENISA EUVD-2026-38153
    role: corroborating
closed_sources: []
evidence:
  - quote: "WID-SEC-2026-2016 — ILIAS: Schwachstelle ermöglicht SQL-Injection — CVE-2026-12789 — Kein Patch verfügbar — öffentlicher Proof-of-Concept vorhanden"
    publisher: BSI WID
  - quote: "SQL injection in ilTrQuery::executeQueries in components/ILIAS/Tracking/classes/class.ilTrQuery.php — ILIAS 11.0 — requires authenticated session"
    publisher: GitHub Advisory GHSA-69G6-PGGC-389P
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-06-23.md
---

BSI WID-SEC-2026-2016 (2026-06-22) flags **CVE-2026-12789**, an SQL injection in ILIAS 11.0's learning-progress tracking — specifically `ilTrQuery::executeQueries` in `components/ILIAS/Tracking/classes/class.ilTrQuery.php` ([BSI WID, 2026-06-22](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2016); [GitHub Advisory GHSA-69G6-PGGC-389P, 2026-06-21](https://github.com/advisories/GHSA-69G6-PGGC-389P)). Exploitation requires an authenticated session (the advisory indicates elevated privileges are needed — PR:High), and the CVSS v4 base score is a low 2.0, reflecting the auth prerequisite and limited data-exposure scope. The operational concern is not the score: **no patch is available** (the vendor has been unresponsive to coordinated disclosure), a proof-of-concept is public, and ILIAS is the dominant open-source LMS across Swiss, German and Austrian universities, vocational schools (Berufsschulen) and public-sector training portals; an ENISA EUVD record exists (EUVD-2026-38153) ([ENISA EUVD, 2026-06-22](https://euvd.enisa.europa.eu/enisa/EUVD-2026-38153)). Below the standard § 2 CVSS/exploitation gate, retained on CH/EU-public-sector-education relevance Until a fix ships: apply WAF rules blocking SQL metacharacter sequences on the tracking endpoints; restrict learning-progress endpoints to enrolled roles; and confirm the ILIAS database account lacks `FILE`/`DROP`/superuser rights (`T1190` Exploit Public-Facing Application, `T1078` Valid Accounts). Hunt DB slow-query / WAF logs for `UNION SELECT` patterns in POST bodies to tracking endpoints and anomalous result-set volumes.
